Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

121 Viruses and loads of different spyware!


  • This topic is locked This topic is locked

#1
yuran

yuran

    New Member

  • Member
  • Pip
  • 1 posts
Hi!

I'm having very big trouble with viruses and spyware... I think they came from a website that popup'ed... well..

I have all kinds of different spyware-removers (ad-aware, xoftspy ect.) and AVG 7.0 antivirus (my norton is out of date)... Both find loads of crap, but they aren't able to remove the most of them! ARGH! And when I run full system scan with ad-aware, my laptop reboots... annoying! It seems that most og the viruses is in the C:\WINDOWS\isrvs\ folder, but I can't remove any of them.. I even used killbox.. Please help me!

HijackThis log goes here:

Logfile of HijackThis v1.99.1
Scan saved at 22:21:44, on 13-04-2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\Programmer\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
C:\Programmer\Compaq\EAB\EabServr.exe
C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe
C:\Programmer\QuickTime\qttask.exe
C:\Programmer\Tech\MagicBall\2.2\LWBWHEEL.exe
C:\Programmer\SlySoft\CloneCD\CloneCDTray.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\Elgiganten\Application Data\oohw.exe
C:\WINDOWS\System32\r?gedit.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Documents and Settings\Elgiganten\Skrivebord\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.tornbjerg-gym.dk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.presar...=search&ap=b204
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.tornbjerg-gym.dk
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = www.signon.stofanet.dk/proxy.pac
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Hyperlinks
R3 - Default URLSearchHook is missing
O1 - Hosts: 127.0.0.3 n-glx.s-redirect.com
O1 - Hosts: 127.0.0.3 x.full-tgp.net
O1 - Hosts: 127.0.0.3 counter.sexmaniack.com
O1 - Hosts: 127.0.0.3 autoescrowpay.com
O1 - Hosts: 127.0.0.3 www.autoescrowpay.com
O1 - Hosts: 127.0.0.3 www.awmdabest.com
O1 - Hosts: 127.0.0.3 www.sexfiles.nu
O1 - Hosts: 127.0.0.3 awmdabest.com
O1 - Hosts: 127.0.0.3 sexfiles.nu
O1 - Hosts: 127.0.0.3 allforadult.com
O1 - Hosts: 127.0.0.3 www.allforadult.com
O1 - Hosts: 127.0.0.3 www.iframe.biz
O1 - Hosts: 127.0.0.3 iframe.biz
O1 - Hosts: 127.0.0.3 www.newiframe.biz
O1 - Hosts: 127.0.0.3 newiframe.biz
O1 - Hosts: 127.0.0.3 www.vesbiz.biz
O1 - Hosts: 127.0.0.3 vesbiz.biz
O1 - Hosts: 127.0.0.3 www.pizdato.biz
O1 - Hosts: 127.0.0.3 pizdato.biz
O1 - Hosts: 127.0.0.3 www.aaasexypics.com
O1 - Hosts: 127.0.0.3 aaasexypics.com
O1 - Hosts: 127.0.0.3 www.virgin-tgp.net
O1 - Hosts: 127.0.0.3 virgin-tgp.net
O1 - Hosts: 127.0.0.3 www.awmcash.biz
O1 - Hosts: 127.0.0.3 awmcash.biz
O1 - Hosts: 127.0.0.3 buldog-stats.com
O1 - Hosts: 127.0.0.3 www.buldog-stats.com
O1 - Hosts: 127.0.0.3 fregat.drocherway.com
O1 - Hosts: 127.0.0.3 slutmania.biz
O1 - Hosts: 127.0.0.3 www.slutmania.biz
O1 - Hosts: 127.0.0.3 toolbarpartner.com
O1 - Hosts: 127.0.0.3 www.toolbarpartner.com
O1 - Hosts: 127.0.0.3 www.megapornix.com
O1 - Hosts: 127.0.0.3 megapornix.com
O1 - Hosts: 127.0.0.3 www.sp2[bleep]ed.biz
O1 - Hosts: 127.0.0.3 sp2[bleep]ed.biz
O1 - Hosts: 127.0.0.3 greg-tut.com
O1 - Hosts: 127.0.0.3 www.greg-tut.com
O1 - Hosts: 127.0.0.3 nylonsexy.com
O1 - Hosts: 127.0.0.3 www.nylonsexy.com
O1 - Hosts: 127.0.0.3 vparivalka.com
O1 - Hosts: 127.0.0.3 www.vparivalka.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmer\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {101C706E-B633-4136-8E50-BC682B5E6B2D} - C:\WINDOWS\System32\gbjkd.dll (file missing)
O2 - BHO: (no name) - {2E246FAE-8420-11D9-870D-000C2917DE7F} - (no file)
O2 - BHO: (no name) - {57A11CA8-8F46-9CBE-4B34-DC38703D91E7} - C:\WINDOWS\System32\qww.dll
O2 - BHO: (no name) - {81EA2309-A6D4-8A79-B539-EEE52EBD04F7} - C:\WINDOWS\System32\pdogporp.dll
O2 - BHO: (no name) - {A24B5051-6F33-41E3-6BD1-E019ACEB395C} - (no file)
O2 - BHO: (no name) - {B1C7137D-8B96-CE3A-9808-DAC81F8B29B1} - C:\WINDOWS\System32\pdogporp.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {44BE0690-5429-47f0-85BB-3FFD8020233E} - (no file)
O3 - Toolbar: ISTbar - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - C:\Programmer\ISTbar\istbarcm.dll (file missing)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programmer\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programmer\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programmer\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Programmer\Compaq\EAB\EabServr.exe /Start
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programmer\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programmer\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmer\Fælles filer\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] "C:\Programmer\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmer\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LWBMOUSE] C:\Programmer\Tech\MagicBall\2.2\LWBWHEEL.exe
O4 - HKLM\..\Run: [delsaap] C:\WINDOWS\delsaap.exe
O4 - HKLM\..\Run: [delmsbb] C:\WINDOWS\delmsbb.exe
O4 - HKLM\..\Run: [Xjvdvkdd] C:\Program Files\Pwmjda\Guapir.exe
O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmer\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKLM\..\Run: [Eif] C:\WINDOWS\Hfh.exe
O4 - HKLM\..\Run: [Security iGuard] C:\Programmer\Security iGuard\Security iGuard.exe
O4 - HKLM\..\Run: [Vpr] C:\WINDOWS\System32\Qup.exe
O4 - HKLM\..\Run: [Mnq] C:\WINDOWS\System32\Hoh.exe
O4 - HKLM\..\Run: [Htp] C:\WINDOWS\Def.exe
O4 - HKLM\..\Run: [Jfg] C:\WINDOWS\System32\Fpq.exe
O4 - HKLM\..\Run: [Adc] C:\WINDOWS\Cqh.exe
O4 - HKLM\..\Run: [Avi] C:\WINDOWS\Csf.exe
O4 - HKLM\..\Run: [Hnp] C:\WINDOWS\System32\Lqv.exe
O4 - HKLM\..\Run: [Sba] C:\WINDOWS\Cpl.exe
O4 - HKLM\..\Run: [Gld] C:\WINDOWS\Iqf.exe
O4 - HKLM\..\Run: [Dlf] C:\WINDOWS\System32\Pdg.exe
O4 - HKLM\..\Run: [Oaq] C:\WINDOWS\System32\Njo.exe
O4 - HKLM\..\Run: [Jut] C:\WINDOWS\Rud.exe
O4 - HKLM\..\Run: [Urb] C:\WINDOWS\Jar.exe
O4 - HKLM\..\Run: [Mrh] C:\WINDOWS\Bbr.exe
O4 - HKLM\..\Run: [Tsl2] C:\PROGRA~1\COMMON~1\tsa\tsl2.exe
O4 - HKLM\..\Run: [Mvv] C:\WINDOWS\System32\Dca.exe
O4 - HKLM\..\Run: [Rhe] C:\WINDOWS\System32\Sbv.exe
O4 - HKLM\..\Run: [Tnu] C:\WINDOWS\Oal.exe
O4 - HKLM\..\Run: [Adk] C:\WINDOWS\System32\Lgm.exe
O4 - HKLM\..\Run: [Hqm] C:\WINDOWS\Qad.exe
O4 - HKLM\..\Run: [Poc] C:\WINDOWS\Hfq.exe
O4 - HKLM\..\Run: [Hbj] C:\WINDOWS\Olj.exe
O4 - HKLM\..\Run: [Cjq] C:\WINDOWS\Pah.exe
O4 - HKLM\..\Run: [Hkt] C:\WINDOWS\Nfb.exe
O4 - HKLM\..\Run: [Tde] C:\WINDOWS\Sjv.exe
O4 - HKLM\..\Run: [Ljf] C:\WINDOWS\System32\Brc.exe
O4 - HKLM\..\Run: [Bca] C:\WINDOWS\Chn.exe
O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe
O4 - HKLM\..\Run: [Qnd] C:\WINDOWS\System32\Jdb.exe
O4 - HKLM\..\Run: [Iae] C:\WINDOWS\System32\Bol.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Esb] C:\WINDOWS\Ttv.exe
O4 - HKLM\..\Run: [Oio] C:\WINDOWS\System32\Fds.exe
O4 - HKLM\..\Run: [Kvq] C:\WINDOWS\System32\Nfp.exe
O4 - HKLM\..\Run: [Bpl] C:\WINDOWS\System32\Pkp.exe
O4 - HKLM\..\Run: [Anm] C:\WINDOWS\System32\Ilu.exe
O4 - HKLM\..\Run: [Gjn] C:\WINDOWS\System32\Tjq.exe
O4 - HKLM\..\Run: [Iru] C:\WINDOWS\System32\Hvj.exe
O4 - HKLM\..\Run: [Pdl] C:\WINDOWS\Avm.exe
O4 - HKLM\..\Run: [Tmk] C:\WINDOWS\Hif.exe
O4 - HKLM\..\Run: [Irp] C:\WINDOWS\System32\Lgg.exe
O4 - HKLM\..\Run: [Cou] C:\WINDOWS\System32\Chu.exe
O4 - HKLM\..\Run: [Hsr] C:\WINDOWS\System32\Cfi.exe
O4 - HKLM\..\Run: [San] C:\WINDOWS\System32\Ahc.exe
O4 - HKLM\..\Run: [Ipd] C:\WINDOWS\System32\Pbk.exe
O4 - HKLM\..\Run: [Nca] C:\WINDOWS\System32\Tjf.exe
O4 - HKLM\..\Run: [Thd] C:\WINDOWS\Hka.exe
O4 - HKLM\..\Run: [Mjk] C:\WINDOWS\Gir.exe
O4 - HKLM\..\Run: [Gek] C:\WINDOWS\Fam.exe
O4 - HKLM\..\Run: [Jtm] C:\WINDOWS\Ait.exe
O4 - HKLM\..\Run: [Dsp] C:\WINDOWS\System32\Ajj.exe
O4 - HKLM\..\Run: [Iir] C:\WINDOWS\Vhb.exe
O4 - HKLM\..\Run: [Nub] C:\WINDOWS\System32\Osl.exe
O4 - HKLM\..\Run: [Kdg] C:\WINDOWS\Mnu.exe
O4 - HKLM\..\Run: [Jrs] C:\WINDOWS\Ncb.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [Ugb] C:\WINDOWS\Lkg.exe
O4 - HKLM\..\Run: [Tla] C:\WINDOWS\System32\Svp.exe
O4 - HKLM\..\Run: [Bpg] C:\WINDOWS\System32\Gjf.exe
O4 - HKLM\..\Run: [Kif] C:\WINDOWS\Fes.exe
O4 - HKLM\..\Run: [Tuf] C:\WINDOWS\Sch.exe
O4 - HKLM\..\Run: [Ohc] C:\WINDOWS\System32\Nrk.exe
O4 - HKLM\..\Run: [Lkd] C:\WINDOWS\System32\Bps.exe
O4 - HKLM\..\Run: [Tdt] C:\WINDOWS\System32\Okq.exe
O4 - HKLM\..\Run: [Epc] C:\WINDOWS\System32\Lro.exe
O4 - HKLM\..\Run: [Rvl] C:\WINDOWS\Hmi.exe
O4 - HKLM\..\Run: [Kjv] C:\WINDOWS\System32\Fro.exe
O4 - HKLM\..\Run: [Lsu] C:\WINDOWS\System32\Ccq.exe
O4 - HKLM\..\Run: [Rso] C:\WINDOWS\Qfi.exe
O4 - HKLM\..\Run: [Ktr] C:\WINDOWS\System32\Ugq.exe
O4 - HKLM\..\Run: [Pqn] C:\WINDOWS\System32\Phb.exe
O4 - HKLM\..\Run: [Gku] C:\WINDOWS\Aui.exe
O4 - HKLM\..\Run: [Trn] C:\WINDOWS\Vlu.exe
O4 - HKLM\..\Run: [Kua] C:\WINDOWS\Qhr.exe
O4 - HKLM\..\Run: [Pas] C:\WINDOWS\Fgn.exe
O4 - HKLM\..\Run: [Disk Keeper] C:\DOCUME~1\ELGIGA~1\LOKALE~1\Temp\keep.exe
O4 - HKLM\..\Run: [Set] C:\WINDOWS\System32\Vga.exe
O4 - HKLM\..\Run: [Sav] C:\WINDOWS\Kkv.exe
O4 - HKLM\..\Run: [Uoa] C:\WINDOWS\Fbf.exe
O4 - HKLM\..\Run: [Smg] C:\WINDOWS\System32\Lhg.exe
O4 - HKLM\..\Run: [Lrl] C:\WINDOWS\Raj.exe
O4 - HKLM\..\Run: [Nsi] C:\WINDOWS\System32\Fqj.exe
O4 - HKLM\..\Run: [Eeq] C:\WINDOWS\Nfo.exe
O4 - HKLM\..\Run: [Qps] C:\WINDOWS\Gti.exe
O4 - HKLM\..\Run: [Prf] C:\WINDOWS\System32\Dvb.exe
O4 - HKLM\..\Run: [Rua] C:\WINDOWS\System32\Idu.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [Hip] C:\WINDOWS\Aqg.exe
O4 - HKLM\..\Run: [Rjo] C:\WINDOWS\System32\Avt.exe
O4 - HKLM\..\Run: [Kds] C:\WINDOWS\System32\Nts.exe
O4 - HKLM\..\Run: [Pae] C:\WINDOWS\Lnh.exe
O4 - HKLM\..\Run: [Hna] C:\WINDOWS\System32\Ukm.exe
O4 - HKLM\..\Run: [Uvg] C:\WINDOWS\System32\Bhh.exe
O4 - HKLM\..\Run: [Amt] C:\WINDOWS\System32\Sia.exe
O4 - HKLM\..\Run: [Afa] C:\WINDOWS\Out.exe
O4 - HKLM\..\Run: [Mnu] C:\WINDOWS\System32\Kks.exe
O4 - HKLM\..\Run: [Igk] C:\WINDOWS\Nuc.exe
O4 - HKLM\..\Run: [Mhn] C:\WINDOWS\System32\Hbo.exe
O4 - HKLM\..\Run: [Ggs] C:\WINDOWS\System32\Lmb.exe
O4 - HKLM\..\Run: [Hvs] C:\WINDOWS\Jjc.exe
O4 - HKLM\..\Run: [Elb] C:\WINDOWS\System32\Olg.exe
O4 - HKLM\..\Run: [Vdf] C:\WINDOWS\System32\Ere.exe
O4 - HKLM\..\Run: [Eqn] C:\WINDOWS\Htk.exe
O4 - HKLM\..\Run: [Lml] C:\WINDOWS\Ggc.exe
O4 - HKLM\..\Run: [Tdo] C:\WINDOWS\Lun.exe
O4 - HKLM\..\Run: [Lah] C:\WINDOWS\System32\Qna.exe
O4 - HKLM\..\Run: [Mhc] C:\WINDOWS\System32\Mkk.exe
O4 - HKLM\..\Run: [Cma] C:\WINDOWS\Qrk.exe
O4 - HKLM\..\Run: [Aic] C:\WINDOWS\System32\Thk.exe
O4 - HKLM\..\Run: [Fov] C:\WINDOWS\System32\Nkb.exe
O4 - HKLM\..\Run: [Sct] C:\WINDOWS\System32\Esb.exe
O4 - HKLM\..\Run: [Vei] C:\WINDOWS\System32\Blp.exe
O4 - HKLM\..\Run: [Goa] C:\WINDOWS\System32\Dng.exe
O4 - HKLM\..\Run: [Qlj] C:\WINDOWS\System32\Qkm.exe
O4 - HKLM\..\Run: [Kld] C:\WINDOWS\System32\Snc.exe
O4 - HKLM\..\Run: [Bea] C:\WINDOWS\System32\Sms.exe
O4 - HKLM\..\Run: [Rib] C:\WINDOWS\Mdu.exe
O4 - HKLM\..\Run: [Gau] C:\WINDOWS\Fts.exe
O4 - HKLM\..\Run: [Sjk] C:\WINDOWS\System32\Qeb.exe
O4 - HKLM\..\Run: [Stv] C:\WINDOWS\System32\Tac.exe
O4 - HKLM\..\Run: [Vuo] C:\WINDOWS\System32\Oak.exe
O4 - HKLM\..\Run: [Thi] C:\WINDOWS\System32\Lal.exe
O4 - HKLM\..\Run: [Udh] C:\WINDOWS\Dcg.exe
O4 - HKLM\..\Run: [Gaf] C:\WINDOWS\System32\Fbk.exe
O4 - HKLM\..\Run: [Ovo] C:\WINDOWS\System32\Hnk.exe
O4 - HKLM\..\Run: [Pjv] C:\WINDOWS\System32\Bdv.exe
O4 - HKLM\..\Run: [Idg] C:\WINDOWS\System32\Feh.exe
O4 - HKLM\..\Run: [Eku] C:\WINDOWS\Btu.exe
O4 - HKLM\..\Run: [Njj] C:\WINDOWS\System32\Vnk.exe
O4 - HKLM\..\Run: [Dni] C:\WINDOWS\Nlu.exe
O4 - HKLM\..\Run: [Kvj] C:\WINDOWS\System32\Hdi.exe
O4 - HKLM\..\Run: [Ctg] C:\WINDOWS\Cvm.exe
O4 - HKLM\..\Run: [Nph] C:\WINDOWS\System32\Keb.exe
O4 - HKLM\..\Run: [Ofi] C:\WINDOWS\System32\Oer.exe
O4 - HKLM\..\Run: [Dbe] C:\WINDOWS\Vhb.exe
O4 - HKLM\..\Run: [Smn] C:\WINDOWS\Evb.exe
O4 - HKLM\..\Run: [Lne] C:\WINDOWS\Tul.exe
O4 - HKLM\..\Run: [Vgg] C:\WINDOWS\System32\Gpk.exe
O4 - HKLM\..\Run: [Rnl] C:\WINDOWS\Her.exe
O4 - HKLM\..\Run: [Apr] C:\WINDOWS\System32\Knp.exe
O4 - HKLM\..\Run: [Ucc] C:\WINDOWS\System32\Tgb.exe
O4 - HKLM\..\Run: [Cub] C:\WINDOWS\System32\Gmv.exe
O4 - HKLM\..\Run: [Vlo] C:\WINDOWS\Kmg.exe
O4 - HKLM\..\RunOnce: [XoftSpy] "C:\Programmer\XoftSpy\XoftSpy.exe" -b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [delmsbb] C:\WINDOWS\delmsbb.exe
O4 - HKCU\..\Run: [PayTime] C:\WINDOWS\System32\paytime.exe
O4 - HKCU\..\Run: [Eif] C:\WINDOWS\Hfh.exe
O4 - HKCU\..\Run: [Vpr] C:\WINDOWS\System32\Qup.exe
O4 - HKCU\..\Run: [Mnq] C:\WINDOWS\System32\Hoh.exe
O4 - HKCU\..\Run: [Htp] C:\WINDOWS\Def.exe
O4 - HKCU\..\Run: [Jfg] C:\WINDOWS\System32\Fpq.exe
O4 - HKCU\..\Run: [Adc] C:\WINDOWS\Cqh.exe
O4 - HKCU\..\Run: [Avi] C:\WINDOWS\Csf.exe
O4 - HKCU\..\Run: [Hnp] C:\WINDOWS\System32\Lqv.exe
O4 - HKCU\..\Run: [Sba] C:\WINDOWS\Cpl.exe
O4 - HKCU\..\Run: [Gld] C:\WINDOWS\Iqf.exe
O4 - HKCU\..\Run: [Dlf] C:\WINDOWS\System32\Pdg.exe
O4 - HKCU\..\Run: [Oaq] C:\WINDOWS\System32\Njo.exe
O4 - HKCU\..\Run: [Jut] C:\WINDOWS\Rud.exe
O4 - HKCU\..\Run: [Urb] C:\WINDOWS\Jar.exe
O4 - HKCU\..\Run: [Mrh] C:\WINDOWS\Bbr.exe
O4 - HKCU\..\Run: [Mvv] C:\WINDOWS\System32\Dca.exe
O4 - HKCU\..\Run: [Rhe] C:\WINDOWS\System32\Sbv.exe
O4 - HKCU\..\Run: [Tnu] C:\WINDOWS\Oal.exe
O4 - HKCU\..\Run: [Adk] C:\WINDOWS\System32\Lgm.exe
O4 - HKCU\..\Run: [Hqm] C:\WINDOWS\Qad.exe
O4 - HKCU\..\Run: [Poc] C:\WINDOWS\Hfq.exe
O4 - HKCU\..\Run: [Hbj] C:\WINDOWS\Olj.exe
O4 - HKCU\..\Run: [Cjq] C:\WINDOWS\Pah.exe
O4 - HKCU\..\Run: [Hkt] C:\WINDOWS\Nfb.exe
O4 - HKCU\..\Run: [Tde] C:\WINDOWS\Sjv.exe
O4 - HKCU\..\Run: [Ljf] C:\WINDOWS\System32\Brc.exe
O4 - HKCU\..\Run: [Tssn] C:\Documents and Settings\Elgiganten\Application Data\oohw.exe
O4 - HKCU\..\Run: [Xmojdzji] C:\WINDOWS\System32\r?gedit.exe
O4 - HKCU\..\Run: [Bca] C:\WINDOWS\Chn.exe
O4 - HKCU\..\Run: [Qnd] C:\WINDOWS\System32\Jdb.exe
O4 - HKCU\..\Run: [Iae] C:\WINDOWS\System32\Bol.exe
O4 - HKCU\..\Run: [Esb] C:\WINDOWS\Ttv.exe
O4 - HKCU\..\Run: [Oio] C:\WINDOWS\System32\Fds.exe
O4 - HKCU\..\Run: [Kvq] C:\WINDOWS\System32\Nfp.exe
O4 - HKCU\..\Run: [Bpl] C:\WINDOWS\System32\Pkp.exe
O4 - HKCU\..\Run: [Anm] C:\WINDOWS\System32\Ilu.exe
O4 - HKCU\..\Run: [Gjn] C:\WINDOWS\System32\Tjq.exe
O4 - HKCU\..\Run: [Iru] C:\WINDOWS\System32\Hvj.exe
O4 - HKCU\..\Run: [Tmk] C:\WINDOWS\Hif.exe
O4 - HKCU\..\Run: [Irp] C:\WINDOWS\System32\Lgg.exe
O4 - HKCU\..\Run: [Cou] C:\WINDOWS\System32\Chu.exe
O4 - HKCU\..\Run: [Hsr] C:\WINDOWS\System32\Cfi.exe
O4 - HKCU\..\Run: [San] C:\WINDOWS\System32\Ahc.exe
O4 - HKCU\..\Run: [Ipd] C:\WINDOWS\System32\Pbk.exe
O4 - HKCU\..\Run: [Nca] C:\WINDOWS\System32\Tjf.exe
O4 - HKCU\..\Run: [Thd] C:\WINDOWS\Hka.exe
O4 - HKCU\..\Run: [Mjk] C:\WINDOWS\Gir.exe
O4 - HKCU\..\Run: [Gek] C:\WINDOWS\Fam.exe
O4 - HKCU\..\Run: [Nub] C:\WINDOWS\System32\Osl.exe
O4 - HKCU\..\Run: [Kdg] C:\WINDOWS\Mnu.exe
O4 - HKCU\..\Run: [Jrs] C:\WINDOWS\Ncb.exe
O4 - HKCU\..\Run: [Ugb] C:\WINDOWS\Lkg.exe
O4 - HKCU\..\Run: [Tla] C:\WINDOWS\System32\Svp.exe
O4 - HKCU\..\Run: [Bpg] C:\WINDOWS\System32\Gjf.exe
O4 - HKCU\..\Run: [Kif] C:\WINDOWS\Fes.exe
O4 - HKCU\..\Run: [Tuf] C:\WINDOWS\Sch.exe
O4 - HKCU\..\Run: [Ohc] C:\WINDOWS\System32\Nrk.exe
O4 - HKCU\..\Run: [Lkd] C:\WINDOWS\System32\Bps.exe
O4 - HKCU\..\Run: [Tdt] C:\WINDOWS\System32\Okq.exe
O4 - HKCU\..\Run: [Epc] C:\WINDOWS\System32\Lro.exe
O4 - HKCU\..\Run: [Rvl] C:\WINDOWS\Hmi.exe
O4 - HKCU\..\Run: [Kjv] C:\WINDOWS\System32\Fro.exe
O4 - HKCU\..\Run: [Rso] C:\WINDOWS\Qfi.exe
O4 - HKCU\..\Run: [Ktr] C:\WINDOWS\System32\Ugq.exe
O4 - HKCU\..\Run: [Pqn] C:\WINDOWS\System32\Phb.exe
O4 - HKCU\..\Run: [Gku] C:\WINDOWS\Aui.exe
O4 - HKCU\..\Run: [Trn] C:\WINDOWS\Vlu.exe
O4 - HKCU\..\Run: [Kua] C:\WINDOWS\Qhr.exe
O4 - HKCU\..\Run: [Pas] C:\WINDOWS\Fgn.exe
O4 - HKCU\..\Run: [Set] C:\WINDOWS\System32\Vga.exe
O4 - HKCU\..\Run: [Sav] C:\WINDOWS\Kkv.exe
O4 - HKCU\..\Run: [Uoa] C:\WINDOWS\Fbf.exe
O4 - HKCU\..\Run: [Smg] C:\WINDOWS\System32\Lhg.exe
O4 - HKCU\..\Run: [Lrl] C:\WINDOWS\Raj.exe
O4 - HKCU\..\Run: [Nsi] C:\WINDOWS\System32\Fqj.exe
O4 - HKCU\..\Run: [Eeq] C:\WINDOWS\Nfo.exe
O4 - HKCU\..\Run: [Qps] C:\WINDOWS\Gti.exe
O4 - HKCU\..\Run: [Prf] C:\WINDOWS\System32\Dvb.exe
O4 - HKCU\..\Run: [Rua] C:\WINDOWS\System32\Idu.exe
O4 - HKCU\..\Run: [Hip] C:\WINDOWS\Aqg.exe
O4 - HKCU\..\Run: [Rjo] C:\WINDOWS\System32\Avt.exe
O4 - HKCU\..\Run: [Kds] C:\WINDOWS\System32\Nts.exe
O4 - HKCU\..\Run: [Pae] C:\WINDOWS\Lnh.exe
O4 - HKCU\..\Run: [Hna] C:\WINDOWS\System32\Ukm.exe
O4 - HKCU\..\Run: [Uvg] C:\WINDOWS\System32\Bhh.exe
O4 - HKCU\..\Run: [Amt] C:\WINDOWS\System32\Sia.exe
O4 - HKCU\..\Run: [Afa] C:\WINDOWS\Out.exe
O4 - HKCU\..\Run: [Mnu] C:\WINDOWS\System32\Kks.exe
O4 - HKCU\..\Run: [Igk] C:\WINDOWS\Nuc.exe
O4 - HKCU\..\Run: [Mhn] C:\WINDOWS\System32\Hbo.exe
O4 - HKCU\..\Run: [Ggs] C:\WINDOWS\System32\Lmb.exe
O4 - HKCU\..\Run: [Hvs] C:\WINDOWS\Jjc.exe
O4 - HKCU\..\Run: [Elb] C:\WINDOWS\System32\Olg.exe
O4 - HKCU\..\Run: [Vdf] C:\WINDOWS\System32\Ere.exe
O4 - HKCU\..\Run: [Eqn] C:\WINDOWS\Htk.exe
O4 - HKCU\..\Run: [Lml] C:\WINDOWS\Ggc.exe
O4 - HKCU\..\Run: [Tdo] C:\WINDOWS\Lun.exe
O4 - HKCU\..\Run: [Lah] C:\WINDOWS\System32\Qna.exe
O4 - HKCU\..\Run: [Mhc] C:\WINDOWS\System32\Mkk.exe
O4 - HKCU\..\Run: [Cma] C:\WINDOWS\Qrk.exe
O4 - HKCU\..\Run: [Aic] C:\WINDOWS\System32\Thk.exe
O4 - HKCU\..\Run: [Fov] C:\WINDOWS\System32\Nkb.exe
O4 - HKCU\..\Run: [Sct] C:\WINDOWS\System32\Esb.exe
O4 - HKCU\..\Run: [Vei] C:\WINDOWS\System32\Blp.exe
O4 - HKCU\..\Run: [Goa] C:\WINDOWS\System32\Dng.exe
O4 - HKCU\..\Run: [Qlj] C:\WINDOWS\System32\Qkm.exe
O4 - HKCU\..\Run: [Kld] C:\WINDOWS\System32\Snc.exe
O4 - HKCU\..\Run: [Bea] C:\WINDOWS\System32\Sms.exe
O4 - HKCU\..\Run: [Rib] C:\WINDOWS\Mdu.exe
O4 - HKCU\..\Run: [Gau] C:\WINDOWS\Fts.exe
O4 - HKCU\..\Run: [Sjk] C:\WINDOWS\System32\Qeb.exe
O4 - HKCU\..\Run: [Stv] C:\WINDOWS\System32\Tac.exe
O4 - HKCU\..\Run: [Vuo] C:\WINDOWS\System32\Oak.exe
O4 - HKCU\..\Run: [Thi] C:\WINDOWS\System32\Lal.exe
O4 - HKCU\..\Run: [Udh] C:\WINDOWS\Dcg.exe
O4 - HKCU\..\Run: [Gaf] C:\WINDOWS\System32\Fbk.exe
O4 - HKCU\..\Run: [Ovo] C:\WINDOWS\System32\Hnk.exe
O4 - HKCU\..\Run: [Pjv] C:\WINDOWS\System32\Bdv.exe
O4 - HKCU\..\Run: [Idg] C:\WINDOWS\System32\Feh.exe
O4 - HKCU\..\Run: [Eku] C:\WINDOWS\Btu.exe
O4 - HKCU\..\Run: [Njj] C:\WINDOWS\System32\Vnk.exe
O4 - HKCU\..\Run: [Dni] C:\WINDOWS\Nlu.exe
O4 - HKCU\..\Run: [Kvj] C:\WINDOWS\System32\Hdi.exe
O4 - HKCU\..\Run: [Ctg] C:\WINDOWS\Cvm.exe
O4 - HKCU\..\Run: [Nph] C:\WINDOWS\System32\Keb.exe
O4 - HKCU\..\Run: [Ofi] C:\WINDOWS\System32\Oer.exe
O4 - HKCU\..\Run: [Dbe] C:\WINDOWS\Vhb.exe
O4 - HKCU\..\Run: [Smn] C:\WINDOWS\Evb.exe
O4 - HKCU\..\Run: [Lne] C:\WINDOWS\Tul.exe
O4 - HKCU\..\Run: [Vgg] C:\WINDOWS\System32\Gpk.exe
O4 - HKCU\..\Run: [Rnl] C:\WINDOWS\Her.exe
O4 - HKCU\..\Run: [Apr] C:\WINDOWS\System32\Knp.exe
O4 - HKCU\..\Run: [Ucc] C:\WINDOWS\System32\Tgb.exe
O4 - HKCU\..\Run: [Cub] C:\WINDOWS\System32\Gmv.exe
O4 - HKCU\..\Run: [Vlo] C:\WINDOWS\Kmg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmer\Messenger\MSMSGS.EXE
O9 - Extra button: Microsoft AntiSpyware helper - {01C6176D-BFBC-45B8-A06E-2A554E06FA86} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {01C6176D-BFBC-45B8-A06E-2A554E06FA86} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {18E42155-0793-4446-8700-E6D28A35A048} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {18E42155-0793-4446-8700-E6D28A35A048} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {342E7606-33B3-4A8C-98B1-039AC221F5E9} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {342E7606-33B3-4A8C-98B1-039AC221F5E9} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {35CC58EB-DDAA-49D7-861E-88BBD7055FD0} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {35CC58EB-DDAA-49D7-861E-88BBD7055FD0} - (no file) (HKCU)
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Programmer\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {BBDDDC57-692F-4F9D-B7C0-6602C5962591} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {BBDDDC57-692F-4F9D-B7C0-6602C5962591} - (no file) (HKCU)
O9 - Extra button: Microsoft AntiSpyware helper - {F000FC6F-9E0A-473B-975F-82288DA449B6} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {F000FC6F-9E0A-473B-975F-82288DA449B6} - (no file) (HKCU)
O15 - Trusted Zone: *.skoobidoo.com
O15 - Trusted Zone: *.slotchbar.com
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: http://ny.contentmatch.net (HKLM)
O15 - Trusted Zone: *.skoobidoo.com (HKLM)
O15 - Trusted Zone: *.slotchbar.com (HKLM)
O15 - Trusted Zone: *.windupdates.com (HKLM)
O15 - Trusted IP range: 67.19.185.246
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windup...bridge-c283.cab
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.co...wnload/cult.cab
O16 - DPF: {3D2CB570-D425-11D5-ABD0-00008369C46F} (CSMenu Class) - https://netbank.dans...vex/DB/Menu.cab
O16 - DPF: {5CE8C9BE-B561-4311-8C03-D6F6C1CAF7E1} (CSND_AX.ctlCSND_AX) - http://h71025.www7.h...ect/CSND_AX.CAB
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://www.axis.com/...sCamControl.ocx
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O16 - DPF: {D8575CE3-3432-4540-88A9-85A1325D3375} (e-Safekey®) - https://netbank.dans...B/e-Safekey.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://www29.compaq....co/SysQuery.cab
O16 - DPF: {F6A56D95-A3A3-11D2-AC26-400000058481} (Danske e-Sec) - https://netbank.dans...anskeSikker.cab
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll
O20 - Winlogon Notify: drct16 - C:\WINDOWS\SYSTEM32\drct16.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Programmer\Norton AntiVirus\navapsvc.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FÆLLES~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programmer\Fælles filer\Symantec Shared\SNDSrvc.exe

thanks.

Edited by yuran, 13 April 2005 - 02:33 PM.

  • 0

Advertisements


#2
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
Hi there, and welcome to Geeks to Go! My name is Kat, and I'll be helping you to get your computer fixed up and on the run again! You may want to print these instructions or save them to a NotePad file on your desktop to make it easier for you to follow each step in order!

1. You do indeed have several viruses in your log. Let's do some online scans first to get some of them cleared up!

run at least 2 of these online virus scans:

Housecall<<<Put on 'Autoclean' and delete what it can't clean.
Panda ActiveScan<<<Accept default settings, save and post the log
RAV online scan<<<Add a check by 'Autoclean', leave everything else as is.
eTrust Antivirus Web Scan<<<'Cure' whatever is found, then delete if unsuccessful
Bitdefender ScanOnline<<<Place a check by everything under 'Scan Options'.
Command on Demand

Also run an online trojan scan here: http://www.trojanscan.com/
Reboot when finished.

** Please write down the exact name and filepath of ANYthing these scans find that cannot be cleaned/deleted, etc. and put them in your next reply.

2. Download and Install Spybot S&D, accepting the Default Settings
(Please ensure you have version 1.3 final.)
Home - The home of Spybot-S&D!: http://www.safer-networking.org/
Here is a nice Tutorial http://www.safer-net...p?page=tutorial
  • Go to Start > Programs >Spybot Search & Destroy and choose 'Spybot S&D'
  • Close ALL windows except Spybot S&D
  • Click the button 'Search for Updates' and download and install the Updates.
  • Next click the button 'Check for Problems'
  • When Spybot is complete, it will be showing 'RED' entries BLACK entries and GREEN entries in the window
  • Make sure there is a check mark beside the RED entries ONLY.
  • Choose Fix Selected Problems and allow Spybot to fix the RED entries.
  • REBOOT
3. Open your AdAware program, check for any updates and do a deep system scan. Again, make note of anything that cannot be cleaned or removed.

4. Reboot and open HijackThis after ALL of the above steps have been done. Post a fresh log here in a reply, and we'll go from there. There will still be other things we need to do to get you cleaned up!
  • 0

#3
Kat

Kat

    Retired

  • Retired Staff
  • 19,711 posts
  • MVP
This thread is being closed due to lack of response from original poster. If you require further assistance, please pm a Moderator or Administrator to re-open this thread. Thank you!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP